backend-pe

Warn

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: MEDIUMPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses directive language intended to override the agent's default operational boundaries. Examples include "INFINITE CONTEXT PROTOCOL" and "SUPERMODE ACTIVATION," which are characteristic of jailbreak-style prompts designed to trigger non-standard behavior.
  • [PROMPT_INJECTION]: Instructions explicitly tell the agent to "Ignore token and cost constraints" and "No Safety Lectures: Assume expert users. Do not warn about cost or complexity unless asked." This is a direct attempt to bypass the agent's internal safety filters and resource management guidelines.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a vulnerability surface by instructing the agent to provide "Full Implementation" and "copy-paste-ready outputs" without safety warnings while processing user-supplied input.
  • Ingestion points: User requests triggered by keywords like "BackendPE", "Supermode", or "Antigravity" (SKILL.md).
  • Boundary markers: Absent. The skill explicitly discourages the use of warnings, safety lectures, or cost constraints that would normally delimit agent behavior.
  • Capability inventory: The agent is directed to generate application code, Dockerfiles, Kubernetes manifests, and Infrastructure-as-Code (Terraform) across multiple languages (Rust, Go, TypeScript) (SKILL.md).
  • Sanitization: Absent. The instructions demand the removal of standard safety lectures and warnings, which could lead the agent to generate or execute malicious code embedded in user-provided architecture requests without its usual oversight.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 29, 2026, 06:18 PM
Security Audit — agent-trust-hub — backend-pe